OAuth Authentication Decisions Not Logged
@sbp đang làm issue này rồi.
Từ ngày 24/4/2026.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
Issue: FINDING-135 - OAuth Authentication Decisions Not Logged
Labels: bug, security, priority:medium, asvs-level:L1
ASVS Level(s): [L1]
Description:
Summary
The OAuth authentication callback handler (/auth endpoint) makes critical authentication decisions but does not log any of them. Both successful logins and failures (invalid/expired state, OAuth provider rejection) occur silently. OAuth is the primary web authentication mechanism, making this a significant gap. The code validates state tokens, calls OAuth providers, and creates sessions without any audit trail, preventing detection of state token brute-force, replay attacks, or compromised accounts.
Details
Affected locations:
src/asfquart/generics.pylines 83-109: OAuth callback without loggingsrc/asfquart/generics.pylines 52-115: Authentication flow without audit
The OAuth callback performs authentication but never logs success or failure, creating complete gap in audit trail for primary web authentication mechanism.
Recommended Remediation
Implement an after_request hook to capture OAuth authentication decisions. In atr/server.py, add @app.after_request handler that checks if request.path == '/auth' and logs oauth_login_success (status 200 with uid) or oauth_login_failure (status 403):
@app.after_request
async def log_oauth_decisions(response: quart.Response) -> quart.Response:
"""Log OAuth authentication decisions for audit trail."""
if quart.request.path == '/auth':
if response.status_code == 200:
# Successful login - extract uid from session
session_data = await asfquart.session.read()
log.info('oauth_login_success', extra={
'asf_uid': session_data.get('uid'),
'remote_addr': quart.request.remote_addr
})
elif response.status_code in (403, 401):
# Failed login
log.warning('oauth_login_failure', extra={
'state_token': quart.request.args.get('state', '')[:8] + '...', # Truncated
'remote_addr': quart.request.remote_addr,
'status': response.status_code
})
return response
Include asf_uid for success cases and failure reason for rejection cases.
Acceptance Criteria
- OAuth authentication success is logged
- OAuth authentication failure is logged
- Log entries include user identity and remote address
- Audit trail is complete for OAuth flow
- Test cases verify OAuth logging
- Unit test verifying the fix
References
- Source reports: L1:7.2.2.md
- Related findings: FINDING-134, FINDING-136, FINDING-250
- ASVS sections: 7.2.2
Priority
Medium
- Ngôn ngữ chính
- Python
- Star
- 7
- Fork
- 13
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của apache/infrastructure-asfquart
-
bug priority
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
documentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
Document OAuth callback consistency rulesCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởdocumentation
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
apache/infrastructure-asfquart#126 · 1 bình luận ·
-
ASVS priority
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
apache/infrastructure-asfquart#85 · 1 bình luận ·
-
Triage and track asfquart issuesCó thể đã có người làm @sbp đã nhận hôm nay. Đang mở
apache/infrastructure-asfquart#134 · 1 người được giao ·
Tất cả issue của apache/infrastructure-asfquart
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Juniper/ansible-junos-stdlib#904 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
pollen-robotics/reachy_mini#1457 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:runtime good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
WATonomous/wato_f1tenth#39 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
FireDynamics/fdsreader#123 ·
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100